CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
Core module · Threat intelligence

In-flight enrichment before correlation — not a separate dashboard silo.

CyberDragon fuses open and commercial intel sources as events flow through the Kafka pipeline. IOCs match Edge protocol events, enterprise syslog, and cloud telemetry in the same indigenous SIEM plane — plus live Threat Atlas context for plant-floor operators.

Threat intelligence in motion

Public intel fused into the same operator narrative as Core.

OTX, Abuse.ch, ThreatFox, MITRE TAXII, and GreyNoise join the kill-chain timeline — this briefing is the public face of that fusion.

What it delivers

Live in Core today.

Multi-source in-flight enrichment on every normalized event

15,093+ IOC corpus matched against Edge and connector telemetry

STIX / TAXII2 exchange with your existing intel platform

Threat Atlas live board for IoT/ICS advisories and ransomware context

GreyNoise noise reduction for internet-facing assets

MITRE ATT&CK and ICS mapping on enriched incidents

SOC

Where every Core module lands

  • Live, partial, and roadmap labeled honestly on the platform page.
  • Detection, risk, compliance, and identity share the same incident.
  • Click a module, then come back to the operator board.
CyberDragon Unified SOC dashboard
How it works

From signal to sealed evidence.

01

Ingest

Edge, syslog, Splunk HEC, and cloud connectors land in Kafka ingest topics.

02

Normalize

Events are schema-normalized so OT protocol semantics and IT logs share one object model.

03

Enrich

OTX, Abuse.ch, ThreatFox, TAXII feeds, and GreyNoise add context before detection rules run.

04

Correlate

Kill-chain windows assemble enriched signals into one incident timeline.

05

Contextualize

Threat Atlas overlays IoT/ICS advisories and KEV entries for operator-readable risk.

06

Respond

Playbooks inherit intel verdicts; evidence vault seals enrichment provenance.

Playbooks

SOAR module in the workspace

  • Run from the incident, not from a disconnected automation island.
  • OT guardrails stay in the path.
  • YAML for teams who version playbooks.
CyberDragon Response playbooks
Key capabilities

Built for regulated IT/OT estates.

Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Signal sources

What feeds this module.

Edge protocol events

Modbus, DNP3, OPC-UA, and MQTT sessions enriched before local or Core detection.

Enterprise syslog

Corporate identity and workstation telemetry joined to the same IOC matches.

Cloud telemetry

AWS CloudTrail and GCP Security Command Center signals in one kill chain.

Vulnerability context

Mirrored NVD and CISA KEV data adds exposure weight to intel hits.

UEBA

User and entity behavior

  • Anomaly signals join the same kill chain as OT protocol events.
  • Useful when identity abuse starts the campaign in enterprise.
  • Not a stand-alone UEBA SKU.
UEBA dashboard
Proof points

Measured in the lab — not marketing adjectives.

15,093
Live IOCs in corpus
6/6
Lab attack scenarios detected
8.0–20.5s
MTTD range
0
False incidents (22.4h baseline)
Lab-validated metrics. Proof of Value results may vary.
FAQ

Frequently asked questions.

Do I need a separate threat intel platform?
No. CyberDragon fuses intel in flight and can exchange STIX/TAXII with your existing TIP if you keep one as system of record.
Does Threat Atlas replace the SIEM?
No. Threat Atlas is an operator board for IoT/ICS context. Enrichment feeds the same incidents your SOC already triages.
Can intel run air-gapped?
Mirrored corpora and Edge buffering support offline plant sites. Sync schedules are tenant-configurable.

See intel enrichment on your own traffic in a 7-day trial.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.